CVE-2021-37705 is a critical authorization bypass vulnerability in Microsoft OneFuzz versions 2.12.0 through 2.30.0, specifically when deployed with the non-default --multi_tenant_domain option. An incomplete authorization check allows any authenticated Azure Active Directory user to make authorized API calls. This can lead to read/write access to sensitive data, tampering, and unauthorized code execution on Azure compute resources. With a CVSS score of 10.0 (Critical), the attack requires no user interaction and has high impact on confidentiality, integrity, and availability. There is currently no public exploit code, active exploitation, or significant community discussion reported for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.12.0, < 2.31.0CPE matchmatch criteria | cpe:2.3:a:microsoft:onefuzz:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.